An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organization to access backend logs that include information related to other organizations.
2024-09-10T15:15:18.420
2024-09-20T16:23:51.397
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortiedrmanager | < 6.2.2 | Yes |
Application | fortinet | fortiedrmanager | 6.0.1 | Yes |